Module DoSProtection

This module bans user when they are sending too much packets within a given timeframe. To see the list of currently banned IPs/ports, use iptables -L.

Configuration options:

NameDescriptionDefault ValueType
enabledIndicate whether the module is activated. trueBoolean
filterA request/response enters module if the boolean filter evaluates to true. Ex: from.uri.domain contains '', from.uri.domain in '', (to.uri.domain in '') && (user-agent == 'Linphone v2') BooleanExpr
time-periodNumber of milliseconds to consider to compute the packet rate 3000Integer
packet-rate-limitMaximum packet rate in packets/seconds,  averaged over [time-period] millisecond(s) to consider it as a DoS attack. 20Integer
ban-timeNumber of minutes to ban the ip/port using iptables 2Integer
iptables-chainName of the chain flexisip will create to store the banned IPs FLEXISIPString
